WP SendFox
WP SendFox has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.
2 independent researchers contributed these findings, one record each. WP SendFox is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.
CVE-2024-49284WP SendFox <= 1.3.1 - Unauthenticated Information Disclosure
Read the full analysisVulnerability Records

WP SendFox
Author
BogdanFix
This plugin lets you capture emails from your WP comment form, WP registration form, WooCommerce checkout form, pages built with Gutenberg and Divi Builder. You can: * add subscribe checkbox to any of these forms * make it pre-checked * make subscription implicit (hidden checkbox) Also you can easily export your WordPress users and/or WooCommerce customers to one of your lists in just 3 clicks, literally. All you need to start using this plugin is your SendFox API key (aka “Personal Access Token”). SendFox website, title and logo are owned by Sumo Group, Inc.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C